Bricks
Bricks Builder · 8 CVEs
Bricks Builder <= 1.12.4 - Unauthenticated SQL Injection via `p` Parameter
Jul 29, 2025
Bricksbuilder <= 1.9.6.1 - Authenticated (Contributor+) Privilege Escalation via create_autosave
Feb 27, 2025
Bricks <= 1.10.1 - Authenticated (Bricks Page Builder Access+) Stored Cross-Site Scripting
Sep 14, 2024
Bricks <= 1.8.1 - Cross-Site Request Forgery via save_settings
Aug 17, 2024
Bricks <= 1.8.1 - Cross-Site Request Forgery via reset_settings
Aug 17, 2024
Bricks Builder <= 1.9.8 - Insecure Direct Object Reference
Jun 22, 2024
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
Jun 4, 2024
The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include…
Oct 28, 2022
The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_sa…
Oct 28, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2025-6495 | Bricks Builder <= 1.12.4 - Unauthenticated SQL Injection via `p` Parameter | HIGH | 0.45% | Jul 29, 2025 |
| CVE-2024-2297 | Bricksbuilder <= 1.9.6.1 - Authenticated (Contributor+) Privilege Escalation via create_autosave | HIGH | 0.36% | Feb 27, 2025 |
| CVE-2023-3410 | Bricks <= 1.10.1 - Authenticated (Bricks Page Builder Access+) Stored Cross-Site Scripting | MEDIUM | 0.31% | Sep 14, 2024 |
| CVE-2023-3408 | Bricks <= 1.8.1 - Cross-Site Request Forgery via save_settings | MEDIUM | 0.24% | Aug 17, 2024 |
| CVE-2023-3409 | Bricks <= 1.8.1 - Cross-Site Request Forgery via reset_settings | MEDIUM | 0.20% | Aug 17, 2024 |
| CVE-2024-4874 | Bricks Builder <= 1.9.8 - Insecure Direct Object Reference | MEDIUM | 0.31% | Jun 22, 2024 |
| CVE-2024-25600 | WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability | CRITICAL | 88.23% | Jun 4, 2024 |
| CVE-2022-3401 | The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code blocks in website conte… | HIGH | 1.70% | Oct 28, 2022 |
| CVE-2022-3400 | The Bricks theme for WordPress is vulnerable to authorization bypass due to a missing capability check on the bricks_save_post AJAX action in versions 1.0 to 1… | MEDIUM | 0.65% | Oct 28, 2022 |
Showing 1 to 8 of 8 CVEs